CVE Vulnerabilities

CVE-2024-28030

Use of NullPointerException Catch to Detect NULL Pointer Dereference

Published: Nov 13, 2024 | Modified: Nov 15, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

NULL pointer dereference in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable denial of service via local access.

Weakness

Catching NullPointerException should not be used as an alternative to programmatic checks to prevent dereferencing a null pointer.

Affected Software

NameVendorStart VersionEnd Version
Intel-mediasdkUbuntufocal*
Intel-mediasdkUbuntuoracular*
Onevpl-intel-gpuUbuntuupstream*

Extended Description

Programmers typically catch NullPointerException under three circumstances:

Of these three circumstances, only the last is acceptable.

Potential Mitigations

References